The Wayback Machine - https://web.archive.org/web/20260404120051/https://docs.docker.com/dhi/
Share feedback
Answers are generated based on the documentation.

Docker Hardened Images


Docker Hardened Images (DHI) provide minimal, secure, and production-ready container images, Helm charts, and system packages maintained by Docker. Designed to reduce vulnerabilities and simplify compliance, DHI integrates easily into your existing Docker-based workflows with little to no retooling required.

DHI is available in the following three subscriptions.

FeatureCommunitySelectEnterprise
Hardened, minimal imagesβœ…βœ…βœ…
Near-zero CVEsβœ…βœ…βœ…
Verifiable SBOMs & SLSA Build L3 provenanceβœ…βœ…βœ…
Full, unsuppressed CVE visibilityβœ…βœ…βœ…
Drop-in adoption, no workflow changesβœ…βœ…βœ…
Full catalog of open source images under Apache 2.0βœ…βœ…βœ…
Built with Docker Hardened System Packagesβœ…βœ…βœ…
Upstream cadence for Docker-released patchesβœ…βœ…βœ…
FIPS/STIG variantsβŒβœ…βœ…
Critical CVE fixes < 7 days with SLA-backed continuous patchingβŒβœ…βœ…
Customizations❌Up to 5Unlimited
Access to Hardened System Packages repositoryβŒβŒβœ…
Full catalog access availableβŒβŒβœ…
Extended Lifecycle Support add-on availableβŒβŒβœ…

Includes:
βœ… +5 years of hardened updates
βœ… Maintains security updates after upstream EOL
βœ… SBOMs & provenance
βœ… Protects long-lived workloads

For pricing and more details, see the Docker Hardened Images subscription comparison.

Explore the sections below to get started with Docker Hardened Images, integrate them into your workflow, and learn what makes them secure and enterprise-ready.